CVE-2023-1427

Photo Gallery by 10Web < 1.8.15 - Admin+ Path Traversal

- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.


We have discovered 36,897 live websites that are affected by CVE-2023-1427.

Test my site




Affected Software

Product  Photo Gallery by 10Web
Category Wordpress Plugins
Vulnerable Domains36,897 live websites (35.15% of Photo Gallery by 10Web install base)
Vulnerable Versions
  • from 0 before 1.8.15
Vulnerable Versions Count324 versions ( 52.68% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Apr 17, 2023
  • Updated - Feb 6, 2025

Credits

  • Nguyen Huu Do (finder)
  • WPScan (coordinator)

CVE-2023-1427 usage by Country

United States9,188 websites



Germany4,523 websites
France2,133 websites
Poland2,026 websites
Russia2,018 websites
GB1,368 websites
Italy1,111 websites
Netherlands1,020 websites
Japan864 websites
Hungary681 websites

CVE-2023-1427 usage by TLD

.com12,898 websites
.de2,368 websites
.org1,852 websites
.ru1,675 websites
.pl1,568 websites
.nl937 websites
.it881 websites
.co.uk873 websites
.net786 websites
.fr738 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-1427

Top websites that are affected by CVE-2023-1427. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.kz Kazakhstan**,***
******.name France**,***
************.ru Russia**,***
***********.org United States**,***
**********.**.uk United States**,***
****************.org United States**,***
***.***.ph Philippines**,***
******************.org United States**,***
*****.edu United States***,***
*********.net Italy***,***
See full domain list

FAQ

CVE-2023-1427 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Photo Gallery by 10Web
A total of 36,897 websites have been identified as vulnerable to CVE-2023-1427, discovered through global website indexing conducted by WebTechSurvey.
Photo Gallery by 10Web is susceptible to CVE-2023-1427 vulnerability.
Photo Gallery by 10Web versions before 1.8.15 are vulnerable to CVE-2023-1427.
Version 1.8.15 of Photo Gallery by 10Web addresses the CVE-2023-1427 security vulnerability.